SB2009021301 - Denial of service in Fail2ban
Published: February 13, 2009 Updated: July 2, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2009-0362)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to filter.d/wuftpd.conf in Fail2ban uses incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry that contains a substring that is interpreted as an IP address.
Remediation
Install update from vendor's website.